CVE-2023-36038 is a Denial of Service vulnerability affecting Microsoft .NET, ASP.NET Core, and Visual Studio 2022. It carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, leading to a complete denial of service without requiring user interaction. While the vulnerability has garnered significant community discussion and media coverage, there is currently no evidence of active exploitation, nor are public exploit modules or proof-of-concept code available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.2, < 17.2.22CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.4, < 17.4.14CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.6, < 17.6.10CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.7, < 17.7.7CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:8.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.